Joern (Code Analysis)
FreeNot checkedIntegrates with Joern's code analysis capabilities to enable static code analysis, vulnerability identification, and code structure understanding through a Pyth
About
Integrates with Joern's code analysis capabilities to enable static code analysis, vulnerability identification, and code structure understanding through a Python interface to Code Property Graphs.
README
MseeP.ai Security Assessment Badge
Joern MCP Server
A simple MCP Server for Joern.
Project Introduction
This project is an MCP Server based on Joern, providing a series of features to help developers with code review and security analysis.
Environment Requirements
- Python >= 3.10 (default 3.12) & uv
- Joern
Installation Steps
Clone the project locally:
git clone https://github.com/sfncat/mcp-joern.git cd mcp-joernInstall Python dependencies:
uv venv .venv source .venv/bin/activate uv sync
Project Structure
├── server.py # MCP Server main program
├── test_mcp_client.py # Test program for joern server and mcp tool
├── test_sc_tools.py # Direct test program for sc tools
├── common_tools.py # Common utility functions
├── server_tools.py # Server utility functions
├── server_tools.sc # Scala implementation of server utility functions
├── server_tools_source.sc # Scala implementation of server utility functions,use sourceCode to get the source code of method
├── requirements.txt # Python dependency file
├── sample_cline_mcp_settings.json # Sample cline mcp configuration file
└── env_example.txt # Environment variables example file
Usage
Start the Joern server:
joern -J-Xmx40G --server --server-host 127.0.0.1 --server-port 16162 --server-auth-username user --server-auth-password password --import server_tools.sc Or joern -J-Xmx40G --server --server-host 127.0.0.1 --server-port 16162 --server-auth-username user --server-auth-password password --import server_tools_source.scIf you are using it under Windows, you may need to set the JVM system variables through the command line or in the system environment variables.
set _JAVA_OPTIONS=-Dfile.encoding=UTF-8set joern logging level to ERROR
set SL_LOGGING_LEVEL=ERROR //windows export SL_LOGGING_LEVEL=ERROR //linuxif you have the following warning
Unable to create a system terminal, creating a dumb terminal (enable debug logging for more information)you can disable it by setting the environment variable
set TERM=dumb export TERM=dumbto restore the default behavior
set TERM=xterm-256color export TERM=xterm-256colorCopy env_example.txt to .env Modify the configuration information to match the joern server startup configuration
Run the test connection: Modify the information in
test_mcp_client.pyto confirm the joern server is working properlyuv run test_mcp_client.py Starting MCP server test... ================================================== Testing server connection... [04/16/25 20:38:54] INFO Processing request of type CallToolRequest server.py:534 Connection test result: Successfully connected to Joern MCP, joern server version is XXXConfigure MCP server Configure the mcp server in cline, refer to
sample_cline_mcp_settings.json.Use MCP server Ask questions to the large language model, refer to
prompts_en.md
Development Notes
.envfile is used to store environment variables.gitignorefile defines files to be ignored by Git version controlpyproject.tomldefines the Python configuration for the project- MCP tool development
- Implement in
server_tools.sc, add definitions inserver_tools.py, and add tests intest_mcp_client.py
- Implement in
Contribution Guidelines
Welcome to submit Issues and Pull Requests to help improve the project.
Welcome to add more tools.
References
Installing Joern (Code Analysis)
This server has no published package — it is built from source. Open the repository and follow its README.
▸ github.com/sfncat/mcp-joernFAQ
Is Joern (Code Analysis) MCP free?
Yes, Joern (Code Analysis) MCP is free — one-click install via Unyly at no cost.
Does Joern (Code Analysis) need an API key?
No, Joern (Code Analysis) runs without API keys or environment variables.
Is Joern (Code Analysis) hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install Joern (Code Analysis) in Claude Desktop, Claude Code or Cursor?
Open Joern (Code Analysis) on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
GitHub
PRs, issues, code search, CI status
by GitHubFilesystem
Secure file operations with configurable access controls.
Memory
Knowledge graph-based persistent memory system.
Template MCP Server
A CLI tool to create a new Model Context Protocol server project with TypeScript support, dual transport options, and an extensible structure
by mcpdotdirectCompare Joern (Code Analysis) with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All development MCPs
